Impact
The Yeti platform accepts DELETE requests to /api/v2/rbac/{id} without checking the caller’s permissions. Users who only have read access can therefore delete access‑control relationships, which can revoke ownership of objects and permanently lock legitimate owners out.
Affected Systems
All Yeti platform releases through version 2.11.0, identified by the cpe:2.3:a:yeti-platform:yeti, are affected. The vulnerability is present in the core Web API code as shown in earlier source versions, before the latest fix.
Risk and Exploitability
The CVSS score of 7.2 classifies this as a high‑severity vulnerability. The EPSS score is below 1 %, indicating a very low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by authenticating with any user account that possesses read permissions, then issuing a DELETE request to remove an RBAC relationship. Because no additional privileges or conditions are required, an attacker with minimal access can permanently alter access control.
OpenCVE Enrichment